[wpt-sync] Sync PR 14522 - SignedExchange: Require nosniff in outer response headers

RESOLVED FIXED in Firefox 67

Status

enhancement
P4
normal
RESOLVED FIXED
7 months ago
5 months ago

People

(Reporter: wptsync, Unassigned)

Tracking

unspecified
mozilla67
Points:
---

Firefox Tracking Flags

(firefox67 fixed)

Details

(Whiteboard: [wptsync downstream], )

Sync web-platform-tests PR 14522 into mozilla-central (this bug is closed when the sync is complete).

PR: https://github.com/web-platform-tests/wpt/pull/14522
Details from upstream follow.

Kouhei Ueno <kouhei@chromium.org> wrote:
>  SignedExchange: Require nosniff in outer response headers
>  
>  To encourage servers to include the nosniff header, this CL makes
>  Chromium reject SXG served without the "X-Content-Type-Options: nosniff"
>  header.
>  
>  Bug: https://github.com/WICG/webpackage/pull/348
>  Change-Id: I5343a8d13a42a3c9144f05d871777d35a20a77b7
>  Reviewed-on: https://chromium-review.googlesource.com/1373430
>  WPT-Export-Revision: 129b2c6a9bbc2c9134a7496527f7cb1582d48eea
PR 14522 applied with additional changes from upstream: 2e19cbe5d5d74821056d4ae2cef435accefaf4ef
Pushed by james@hoppipolla.co.uk:
https://hg.mozilla.org/integration/mozilla-inbound/rev/8e0c10dc5825
[wpt PR 14522] - SignedExchange: Require nosniff in outer response headers, a=testonly
Pushed by james@hoppipolla.co.uk:
https://hg.mozilla.org/integration/mozilla-inbound/rev/768b0b422609
[wpt PR 14522] - SignedExchange: Require nosniff in outer response headers, a=testonly
Status: NEW → RESOLVED
Closed: 5 months ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla67
You need to log in before you can comment on or make changes to this bug.